Field note
Shared logins still sitting on the pay-run screen
Maker-checker is theatre when both roles are used from the same saved password on the operations PC.
Application-control questionnaires almost always say that the pay run is prepared by one person and approved by another. The live system often tells a shorter story: a generic “PAYROLL” user, a password on a sticky note, and an approval timestamp a few seconds after the batch was built.
We do not treat that as a morality play. We treat it as a financial-statement risk. Anyone with that login can change a bank account, insert an adjustment, and approve the same batch.
The fix is rarely a new module. It is named accounts, a checker who does not hold edit rights, and a short report of user IDs on the pay-run audit trail that finance actually reads before the bank file goes out.
If your suite cannot separate prepare and approve, say so in the engagement letter and design a compensating check. Pretending the control exists helps no one when a reversal has to be explained.